Skip to main content

How does Konfir keep my data secure?

Konfir is ISO 27001 certified and uses security measures to protect your data, including encrypted connections, secure APIs, and platform-level safeguards.

Written by Jacob

Summary

Konfir protects your data at every step of the verification process. Every connection is encrypted, every access is read-only and time-limited, and your login credentials are never seen or stored.


Connection Security

When you connect a source (Banking, HMRC, or Payroll), the connection is made using secure, encrypted APIs:

  • You log in directly with the data provider using their secure authentication

  • Konfir receives only a defined, limited set of data

  • Access is one-time and read-only

  • Access is automatically revoked once your data is retrieved

Why this matters: Unlike traditional referencing, no data is ever sent by email, spreadsheets, or PDFs between HR teams. Everything is handled through secure, encrypted channels with audit trails.


Platform Security

Konfir protects your data through multiple reinforcing layers:

  • Encryption: All data is encrypted both in transit and at rest using industry-standard protocols

  • Role-based access controls: Only authorised personnel can access sensitive systems, with permissions tailored to their role

  • Monitoring & audit logging: Continuous monitoring detects anomalous behaviour

  • Operational security testing: Regular vulnerability management and independent testing

  • Secure cloud infrastructure: Hosted on AWS, designed for resilient and secure operation


Independent certification

Konfir's security practices are independently verified:

  • ISO 27001 - International standard for information security management

  • UK Digital Identity & Attributes Trust Framework (DIATF) - Registered

  • UK GDPR & Data Protection Act 2018 - Fully compliant

Did this answer your question?